CVE-2026-18431: Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write

Published Aug 26, 2026
·
Updated

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.

Affected Software

2 affected components
Avada (WordPress theme)<=7.16
Fusion Builder (WordPress plugin)<=3.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Avada (WordPress theme) to a version that resolves this vulnerability.

    Fixed in 7.16
  2. Upgrade

    Upgrade Fusion Builder (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 3.16

Event History

Aug 26, 2026
CVE Published
via MITRE·06:08 AM
Data Sourced
via MITRE·06:08 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to exploitation?

A site is exposed only if it has both the Avada theme and the Fusion Builder plugin installed and active, at affected versions, and it contains the required administrator-authored content. The issue can be exploited remotely without authentication.

2

What access does an attacker need?

No account, privileges, or user interaction are required. An unauthenticated attacker can exploit the weakness chain to write attacker-controlled files and potentially execute PHP code on the server.

3

What is the likely impact of successful exploitation?

Successful exploitation can allow arbitrary PHP file creation and execution, leading to remote code execution and complete site compromise.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203